Security News

US Seizes Domains Behind Two Chinese-Linked Hacking Tools Used Against Critical Infrastructure

CyberScoop · 9 Oct 2026
Key Takeaway Review your Microsoft Exchange and VPN exposure now by enforcing multi-factor authentication, blocking repeated password guessing, and patching internet-facing systems promptly.

The US Justice Department and FBI have seized domain names for two hacking tools linked to the Chinese government-connected group Flax Typhoon. The tools are Microscan, which scans for vulnerabilities, and FishHub, a spearphishing tool. Both were created by Integrity Technology Group, a China-based company the US sanctioned last year and previously accused of being behind a large botnet. The seizures were court-authorised in the Western District of Pennsylvania, and are intended to deny hackers access to the tools.

The FBI, CISA and the NSA also released a joint advisory. It says the actors combine automated scanning, large-scale botnets and hands-on exploitation to steal sensitive data. Methods named include cross-site scripting attacks and password spraying on Microsoft Exchange servers, persistence through VPN software, and the use of scripts to take emails and credentials. Law enforcement said Integrity Tech used a Mirai-variant botnet of internet-connected devices to support Microscan.

Reported Microscan targets include a South Carolina power company, airports in Japan and Poland, and critical infrastructure firms and universities in Taiwan. FishHub, which installs malware after a victim is phished, has hit Taiwanese universities. CISA's Chris Butera said Chinese government-affiliated actors continue to position themselves inside critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing.

Flax Typhoon Critical Infrastructure Phishing Microsoft Exchange Botnet

Summarised by CISO AI from CyberScoop, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.